N8Technologyhub

Friday, 4 March 2016

How To Install Mac OS 10.8 in Vmware

Mac OS X 10.8 Mountain Lion on Vmware Workstation 9


Owning a Macbook or Apple product is always my dream. I dreamt on it, yet it is way too expensive for a student like me. Therefore, Hackintosh is a perfect solution for me.

Here, I am going to go through the steps of installing Mountain Lion on VM. It is an easy task.

You have to prepare these to start your work.
  •  Hackintosh Compatible Hardware :You must have an Intel CPU which has virtualization enabled.(You will get a guide on enable it on below.)
  • Installed VMware Workstation 9 :This is the platform I will go through.                          (VMware player works as well.)
  • OS X 10.8 Mountain Lion Retail VMware Image: Download from torrent. Download or Download
    Can't download this file? I recommend you to install this torrent software.
  • VMsvga2_v1.2.3.pkg: It is used for Mac display.
Now, let's go!

Step 1

Restart your computer and enter your bios.
Navigate to Advance Bios Feature and look for Virtualization Technology.
Enable it and you are done.

Step 2

Extract OS X 10.8 Mountain Lion Retail VMware Image.7z file.
You will get to see three folders.


OS X 10.8 Mountain Lion folder contains the image file.

VMware Unlocker - Hardware Virtualization Bypasser folder contains file that help you pass the restriction for VMware if your machine does not support Virtualization technology. (Most of us wouldn't use this.)

VMware Unlocker - Mac OS X Guest folder contains file to unlock Mac OS X Operating System in VMware workstation.



Step 3
Completely close your VMware Workstation.
Execute install.cmd in VMware Unlocker – Mac OS X Guest -> VMware 8.x Series -> VMware Workstation Unlocker - Windows folder.
Make sure to run it as administrator for it to work.



Step 4
Start your VMware Workstation. Go to File ->Open and Navigate to OS X 10.8 Mountain Lion.vmx and open it.



Then click Edit virtual machine settings to configure it.



Adjust your memory to at least 2GB and your processor to 2 cores as well as accelerate 3D graphics to provide a smooth environment.


Then, navigate to the Options tab to configure the operating system to Apple Mac OS X and version to Mac OS X 10.8 64-bit. This shows up after you successfully installed the install.cmd in step 3.


Step 5
Power on this virtual machine and follow the on-screen solution to set up your operating system.



After all sorts of clicking next and a few minutes of time, you finally succeed in login to Mountain Lion. Congratulations! But this is still not the end.


Step 6
You have to install VMware tools to have a better experience. So, we navigate to folder VMware Unlocker - Mac OS X Guest -> VMware 8.x Series -> Tools and mount darwin.iso.
 

Now, let's try to install VMware tools in Mountain Lion.

You probably will encounter error on finishing the installation.

But never mind, it is actually "installed". You can find it out after you restart your system.


Step 7
Now, you might encounter screen flickering while opening launchpad now. No worries, I got your back. Copy the VMsvga2_v1.2.3.pkg into Mountain Lion and runs it.

Here, you got yourself ready a HOT pancake!


You got no glitches now for your brand new Mountain Lion.

The Graphics here shows that you are currently using VMware SVGA II 128MB. It is the display to use with Mac OS after you successfully installed VMsvga2_v1.2.3.pkg.

Note 1. VMware couldn't detect your display card. It will only give your virtual machine a maximum of 128MB nVRAM. It is not really compatible with Mac OS, so we installed VMsvga2_v1.2.3.pkg.

and now

CONGRATULATIONS!

You can show off your hackintosh to your friends now.
It is just as smooth as real Mac with my current computer specifications. Just some lagging while launching the launchpad. This is not a real BIG deal.


Feel free to ask me any questions or give me any advice to make me better. Thank you.

Wednesday, 2 March 2016

MWC 2016: What We Want To See

MWC 2016: what we want to see


MWC 2016: what we want to see
MWC 2015 has been and gone, but the products which were announced there aren't likely to be forgotten any time soon, from the flagship HTC One M9 and Samsung Galaxy S6smartphones, to the stylish Huawei Watch and the innovative Galaxy S6 Edge - and those are just some of the highlights.
But we're already looking towards next year's show and thinking of all the things we want to see, whether it's improvements on this year's offerings or completely new ideas, there's a lot we're hoping for.

A truly bendy phone

Corning Willow Glass
Samsung and LG have teased us with the likes of the Galaxy S6 Edge and the LG G Flex 2, but we want someone to take these ideas to the next step, with a bendable phone or at the very least a phone which makes good use of its curves.
Hopefully something will manage that at MWC 2016 and hopefully it will be a flagship, rather than being designed as a niche device.

Bigger batteries rather than slimmer phones

battery
The Samsung Galaxy S6 is a brilliant phone, but in focusing on design and making it as slim as possible Samsung forgot about one of the key things - good battery life, and many other manufacturers are almost as guilty of this.
We'll happily take a thicker phone if it means a bigger battery, we'll even pay a little more, so hopefully the powers that be, or the people that make, are listening, and many of the phones announced at MWC 2016 have great battery life.

Battery innovation

battery icon
As well as thicker batteries how about new batteries? The same type of juice packs have been powering our phones for years and the reality is that they're just not very good.
New battery technology is being researched all the time and hopefully by next year some of that will have gone past the research stage and been implemented into smartphones.Origami batteries anyone? Or how about super-fast charging ones?'

HTC One M10

HTC One M9
The HTC One M9 launched at MWC 2015 and there's a good chance we'll see the HTC One M10 at MWC 2016. But what specifically do we want? A better battery would be a good start, but beyond that it needs to be substantially different to and better than the M9.
That might mean changing the admittedly brilliant design, or maybe HTC will achieve it by adding new features to the phone, like a fingerprint or iris scanner, but the company needs to do something, because as great as the M9 is it feels like HTC's treading water.

Samsung Galaxy S7

Galaxy S6
There's also a good chance we'll see the Samsung Galaxy S7 at MWC 2016 and we hope so too, especially after how impressive the S6 was.
Battery life is a key concern again and it would be good if Samsung could return some of the features it cut from the S6, like a microSD card slot and a water resistant build.

More power, without the heat

processor
Each year we see ever more powerful phones, but this year the mobile chip of choice - the Snapdragon 810, has been subject to overheating concerns.
No-one wants a toasty phone, especially not when excessive heat can risk damaging the innards too, so we hope whatever phones are announced at MWC 2016 are even more powerful, but without the heat. This shouldn't be a problem, in fact Fujitsu already claims to have the answer.

Smartwatches hitting their stride

LG Watch Urbane
It's still early days when it comes to smartwatches. The latest ones like the LG Watch Urbane, the Huawei Watch and the Apple Watch are finally starting to look less like tech and more like fashion, but they still have a way to go before they're likely to convince the masses to ditch their dumb-watches.
There needs to be other improvements too, with battery life key among them. We hope that by MWC 2016 many of the problems faced by smartwatches will have been solved and they'll be ready for prime time.

Modular mayhem

Project Ara
We were hoping Google would show off Project Ara at MWC 2015, but sadly that didn't happen. Still, we doubt we'll have to wait till MWC 2016 for a good look at it, no, what we want by then is for there to be a whole heap of modular phones, or at least a whole heap of modules for phones.
Then we'll be free to fix whatever the manufacturers inevitably get wrong/not to our tastes. No fingerprint scanner? Add one. Rubbish camera? Switch it for a better one. Battery too small? Put a bigger one in. And never buy a whole new phone again. Maybe.

A bigger Windows Phone presence

Lumia 930
Windows Phone has had a tough time up against the might of Android and iOS and it feels like an eternity since the last Lumia flagship. But Windows 10 Mobile should be out later this year and hopefully that will kick-start production of more handsets.
We probably won't have to wait until 2016 for a new flagship, but hopefully a new OS will lead to a boost in popularity and with it a slew of new Windows Phone devices at MWC 2016.

Surprises

MWC
Surprises are always fun. Well, not always, there was that one time with the trampoline and the custard, but we don't talk about it.
When it comes to MWC more powerful devices are a given, new phones from HTC and Samsung are likely and everything else we've hoped for, well, we already hope for it, so it won't be much of a surprise.
So surprise us assorted tech makers. Bring us something we can't predict. Just make sure it's not something rubbish. And there's no custard. We never want to see custard again

Monday, 22 February 2016

Apple Asked To Pay $625M To Patent Troll In FaceTime Lawsuit

Apple Asked To Pay $625M To Patent Troll In FaceTime Lawsuit

Apple slapped with a huge $625 million Patent Troll verdict over FaceTime, VPN patents
A U.S. court has directed Apple to pay $625 million to infamous patent troll VirnetX for infringing on patents used in its iMessage and FaceTime services.
Commonly referred to as a troll, VirnetX, a Nevada holding company, has made almost majority of its revenue from patent licensing and lawsuits by suing a number of tech companies over the past decade. In 2014, it settled a dispute with Microsoft over patents used in Skype by pocketing $24 million in the process. Similarly, it was able to churn out $200 million from the Redmond based company over the alleged use of Virtual Private Network (VPN) patents in FaceTime video chats via a 2010 case.
“We are thankful for the jurors’ hard work and attention in this case, and for reaching a just verdict,” said VirnetX attorney Jason Cassady in a statement. “The jury saw what we have been saying all along: Apple has been infringing VirnetX’s patented technology for years.”
According to the company’s lawyers, the jury award included royalties based on an earlier patent infringement finding in favor of VirnetX.
Apple on Wednesday filed court papers asking U.S. District Judge to declare a mistrial, saying VirnetX’s attorneys had misled the jury during closing arguments.
“We are surprised and disappointed by the verdict and we’re going to appeal. Our employees independently designed this technology over many years, and we received patents to protect this intellectual property. All four of VirnetX’s patents have been found invalid by the patent office. Cases like this simply reinforce the desperate need for patent reform,” it said in a statement.
In November 2012, a jury found Apple infringed four VirnetX patents with its iPhone, iPod Touch and iPad products, as well as with its Mac computers, awarding $368.2 million in damages. However, Apple later tweaked its services, but VirnetX claimed that the changes were not enough.

How To Install Kali Linux On Android Smartphone

Install Kali Linux on your Android device and develop a portable penetration testing environment
Kali Linux, a secure distribution of Linux, is one of the most widely used OS among ethical hackers  (and unethical hackers). The reason is that Kali Linux has almost every tool required for pentesting pre-installed. And a great back end support from Offensive Security make it a great platform for beginners as well as professionals. Kali Linux is a successor of BackTrack OS which was also developed by Offensive Security.
The developers at Offensive Security have been working extensively for developing a dedicated operating system for cyber-security researchers. Along with ARM devices, Kali Linux is available for Android too.
The installation process is very simple and straightforward. If you have a rooted Android phone having at least 5GB of free storage and a fast internet connection (to download repository files), then everything else is just a matter of few taps on your smartphone.
First of all install Linux Deploy app from Play Store.
Now make sure that your phone is in the required state for installation. That is, make sure that your phone is rooted, having 5GB of free space, an internet connection with decent speed (and you are patient enough to wait for Kali to bootstrap from the network).
Root privilege is required because Kali will install itself in chroot mode. Which means that allowed access will be restricted to specified directory (acting as root directory) and their children.
Step 2 is running the app, and selecting Kali Linux in the distribution tab. Optionally, you can choose your architecture, verify that the Kali mirror is correct, set your installation type and location on your Android device, etc. Generally speaking, the defaults provided by Linux Deploy are good to begin with.
Once all the settings are at place, hit the “install” button and app will start a Kali Linux bootstrap directly from repositories of Offensive Security. Depending on your Internet connection speed, this process could take a while. You’ll be downloading a base install of Kali Linux (with no tools) at minimum.
When the installation is complete, you can have Linux Deploy automatically mount and load up your Kali Linux chroot image. This also includes the starting of services such as SSH and VNC for easier remote access. All of this is automatically done by hitting the “start” button. You should see Linux Deploy setting up your image with output similar to the following:
Kali Linux
At this stage, Linux Deploy has started a VNC and SSH server inside your chrooted Kali image. You can connect to the Kali session remotely using the IP address assigned to your Android device (in my case, 10.0.0.10).
Logging In:
You can now access your Kali Linux instance with either VNC or Secure Shell(SSH). The required credentials are-
For VNC password is “changeme”
For SSH username is “android” and password is again “changeme”
This is what it all looks like on your device:
Linux localhost 3.4.5-447845 #1 SMP PREEMPT Fri Apr 12 17:22:34 KST 2013 armv7l
Kali GNU/Linux 1.0 [running on Android via Linux Deploy] android@localhost:~$ sudo su
root@localhost:/home/android# df
Filesystem 1K-blocks Used Available Use% Mounted on
/dev/loop3 4180944 667268 3304012 17% /
tmpfs 952708 80 952628 1% /dev
tmpfs 952708 0 952708 0% /dev/shm
root@localhost:/home/android#
root@localhost:/home/android# apt-get update
Hit http://http.kali.org kali Release.gpg
Hit http://http.kali.org kali Release
Hit http://http.kali.org kali/main Sources
Hit http://http.kali.org kali/contrib Sources
Hit http://http.kali.org kali/non-free Sources
Hit http://http.kali.org kali/main armel Packages
Hit http://http.kali.org kali/contrib armel Packages
Hit http://http.kali.org kali/non-free armel Packages
Ign http://http.kali.org kali/contrib Translation-en_US
Ign http://http.kali.org kali/contrib Translation-en
Ign http://http.kali.org kali/main Translation-en_US
Ign http://http.kali.org kali/main Translation-en
Ign http://http.kali.org kali/non-free Translation-en_US
Ign http://http.kali.org kali/non-free Translation-en
Reading package lists… Done
root@localhost:/home/android#
Memory Considerations:
If left unchanged, Linux Deploy will automatically set an image size of around 4 GB, for a “naked” installation of Kali. If you would like to install additional Kali tools down the road, you might want to consider using a larger image size, which is configurable via the settings in Linux Deploy.
Quick Tip: Prefer SSH over VNC while logging into your OS. This will save you a lot of time.
Post your further queries in the comment box to get them resolved.

Thursday, 11 February 2016

What’s Penetration Testing ?

Pen tests can be automated with software applications or they can be performed manually. Either way, the process includes gathering information about the target before the test (reconnaissance), identifying possible entry points, attempting to break in (either virtually or for real) and reporting back the findings.
The main objective of penetration testing is to determine security weaknesses. A pen test can also be used to test an organization’s security policy compliance, its employees’ security awareness and the organization’s ability to identify and respond to security incidents.
Penetration tests are sometimes called white hat attacks because in a pen test, the good guys are attempting to break in.

What’s Kali Linux ?

Kali Linux is a Debian-based Linux distribution aimed at advanced Penetration Testing and Security Auditing. Kali contains several hundred tools aimed at various information security tasks, such as  Penetration Testing, Forensics and Reverse Engineering. Kali Linux is developed, funded and maintained by Offensive Security, a leading information security training company.

Top 20 Penetration Testing Tool In Kali linux 2.0


1. Metasploit

2ENTk2K2This is the most advanced and popular Framework that can be used to for pen-testing. It is based on the concept of ‘exploit’ which is a code that can surpass the security measures and enter a certain system. If entered, it runs a ‘payload’, a code that performs operations on a target machine, thus creating the perfect framework for penetration testing.
It can be used on web applications, networks, servers etc. It has a command-line and a GUI clickable interface, works on Linux, Apple Mac OS X and Microsoft Windows. This is a commercial product, although there might be free limited trials available.

2. Armitage

titleArmitage is a scriptable red team collaboration tool for Metasploit that visualizes targets, recommends exploits, and exposes the advanced post-exploitation features in the framework.
Through one Metasploit instance, your team will:

  • Use the same sessions
  • Share hosts, captured data, and downloaded files
  • Communicate through a shared event log.
  • Run bots to automate red team tasks.

3. Wireshark

Wireshark_icon.svgThis is basically a network protocol analyzer –popular for providing the minutest details about your network protocols, packet information, decryption etc. It can be used on Windows, Linux, OS X, Solaris, FreeBSD, NetBSD, and many other systems. The information that is retrieved via this tool can be viewed through a GUI, or the TTY-mode TShark utility.

4. Burpsuite

burpsuiteBurp suite is also essentially a scanner (with a limited “intruder” tool for attacks), although many security testing specialists swear that pen-testing without this tool is unimaginable. The tool is not free, but very cost effective. Take a look at it on below download page. It mainly works wonders with intercepting proxy, crawling content and functionality, web application scanning etc.  You can use this on Windows, Mac OS X and Linux environments.

5. Acunetix

gNZYvNn5Acunetix is essentially a web vulnerability scanner targeted at web applications. It provides SQL injection, cross site scripting testing, PCI compliance reports etc. along with identifying a multitude of vulnerabilities. While this is among the more ‘pricey’ tools.

6. John The Ripper

jtrAnother password cracker in line is, John the Ripper. This tool works on most of the environments, although it’s primarily for UNIX systems. It is considered one of the fastest tools in this genre. Password hash code and strength-checking code are also made available to be integrated to your own software/code which I think is very unique. This tool comes in a pro and free form.

7. Social Engineer Toolkit

setThe Social-Engineer Toolkit (SET) is a unique tool in terms that the attacks are targeted at the human element than on the system element. It has features that let you send emails, java applets, etc containing the attack code. It goes without saying that this tool is to be used very carefully and only for ‘white-hat’ reasons.  It has a command-line interface, works on Linux, Apple Mac OS X and Microsoft Windows.

8. Nmap

nmap-logo-256x256“Network Mapper” though not necessarily a pen-testing tool, it is a must-have for the ethical hackers. This is a very popular tool that predominantly aids in understanding the characteristics of any target network. The characteristics can include: host, services, OS, packet filters/firewalls etc.  It works on most of the environments and is open sourced.

9. BeEF

1214850BeEF is short for The Browser Exploitation Framework. It is a penetration testing tool that focuses on the web browser- what this means is that, it takes advantage of the fact that an open web-browser is the window(or crack) into a target system and designs its attacks to go on from this point on . It has a GUI interface, works on Linux, Apple Mac OS X and Microsoft Windows.

10. Aircrack-ng

aircrack-ng-new-logoAircrack-ng is an 802.11 WEP and WPA-PSK keys cracking program that can recover keys once enough data packets have been captured. It implements the standard FMS attack along with some optimizations like KoreK attacks, as well as the PTW attack, thus making the attack much faster compared to other WEP cracking tools.
In fact, Aircrack-ng is a set of tools for auditing wireless networks.

11. Sqlmap

sqlmapSqlmap is again a good open source pen testing tool. This tool is mainly used for detecting and exploiting SQL injection issues in an application and hacking over of database servers. It comes with command-line interface. Platform: Linux, Apple Mac OS X and Microsoft Windows are supported platforms.

12. Ettercap

ettercap-english-1Ettercap is a free and open source network security tool for man-in-the-middle attacks on LAN. It can be used for computer network protocol analysis and security auditing. It runs on various Unix-like operating systems including Linux, Mac OS X, BSD and Solaris, and on Microsoft Windows.

13. Hydra

xhydraHydra is a parallelized login cracker which supports numerous protocols to attack. It is very fast and flexible, and new modules are easy to add. This tool makes it possible for researchers and security consultants to show how easy it would be to gain unauthorized access to a system remotely.
It supports: Cisco AAA, Cisco auth, Cisco enable, CVS, FTP, HTTP(S)-FORM-GET, HTTP(S)-FORM-POST, HTTP(S)-GET, HTTP(S)-HEAD, HTTP-Proxy, ICQ, IMAP, IRC, LDAP, MS-SQL, MySQL, NNTP, Oracle Listener, Oracle SID, PC-Anywhere, PC-NFS, POP3, PostgreSQL, RDP, Rexec, Rlogin, Rsh, SIP, SMB(NT), SMTP, SMTP Enum, SNMP v1+v2+v3, SOCKS5, SSH (v1 and v2), SSHKEY, Subversion, Teamspeak (TS2), Telnet, VMware-Auth, VNC and XMPP.

14. Maltego

splash303-new3Maltego is a program built into Kali Linux that lets you do reconnaissance on any person, by scraping up data from all publicly available areas of the Internets. Maltego is used for information gathering and data-mining, and can be useful for anyone who needs to gather data on a person or company

15. Nikto

m_KaliNiktoNikto is an Open Source (GPL) web server scanner which performs comprehensive tests against web servers for multiple items, including over 6400 potentially dangerous files/CGIs, checks for outdated versions of over 1200 servers, and version specific problems on over 270 servers.

16. Sqlninja

logoSqlninja, as the name indicates is all about taking over the DB server using SQL injection in any environment. This product by itself claims to be not so stable its popularity indicates how robust it is already with the DB related vulnerability exploitation. It has a command-line interface, works on Linux, Apple Mac OS X and not on Microsoft Windows.

17. HaCoder.py

12196139_117521298609075_5015584866505144610_nHaCoder.py is Python based FUD RAT (fully undetectable remote administration tool) used for remote control infected PC. It’s coded by Luka Sikic using Python socket programming. Credits goes to Technic Dynamic for idea about AES Encrypted communication between infected PC and control machine. Download Here.

18. CORE Impact

IMPACT.logo-300x81CORE Impact Pro can be used to test mobile device penetration, network/network devise penetration, password identification and cracking, etc. It has a command-line and a GUI clickable interface, works Microsoft Windows. This is one of the expensive tools in this line.

19. Canvas

logo_canvasNetworkImmunity’s CANVAS is a widely used tool that contains more than 400 exploits and multiple payload options. It renders itself useful for web applications, wireless systems, networks etc. It has a command-line and GUI interface, works on Linux, Apple Mac OS X and Microsoft Windows. It is not free of charge and can more information can be found at below page.

20. Retina

Retina-logoAs opposed to a certain application or a server, Retina targets the entire environment at a particular company/firm. It comes as a package called Retina Community. It is a commercial product and is more of a vulnerability management tool more than a pen-testing tool. It works on having scheduled assessments and presenting results. Check out more about this package at below page.